For years, one of the most frustrating privacy gaps in everyday messaging was the green bubble problem: send a photo from an iPhone to an Android phone, and it would travel over SMS or MMS — an unencrypted protocol designed in the 1990s. Anyone with the right tools on your carrier’s network could intercept it. The file would be compressed into near-uselessness and arrive without any encryption in transit.
In May 2026, that changed. Apple and Google jointly announced the rollout of end-to-end encrypted RCS messaging between iPhone and Android — the first time this has been possible across the two dominant smartphone platforms at scale. The Electronic Frontier Foundation called it a “victory.” Privacy advocates who had been pushing for this for years celebrated.
The celebration is warranted. But the upgrade covers a specific slice of your privacy — and understanding exactly what it protects, and what it doesn’t, is important for anyone who relies on messaging to share photos, files, and personal data.
What RCS Is and Why It Matters
RCS stands for Rich Communication Services. It was designed as the successor to SMS and MMS — a messaging standard that supports longer messages, read receipts, typing indicators, group chats, higher-quality photo and video sharing, and crucially, encryption.
Before the May 2026 update, RCS on Android-to-Android conversations had already supported end-to-end encryption via Google’s implementation for several years. The problem was cross-platform: when an iPhone user and an Android user messaged each other, the conversation fell back to the older, unencrypted SMS/MMS standard.
The new standard changes that. Apple integrated E2EE RCS support into iOS 26.5, with a lock icon appearing in chats to confirm encryption is active. Google Messages already had encryption for Android-to-Android RCS; the update extended that to cross-platform conversations. Both Apple and Google have confirmed that neither company, nor the carrier, can read the content of these encrypted conversations.
For photo sharing, this is meaningful. A photo sent from an iPhone to an Android phone now travels through an encrypted channel from device to device. The carrier cannot read it. The company providing your cell service cannot log it. An attacker intercepting traffic on the network cannot view it.
What End-to-End Encryption Actually Means
Before going further, it’s worth being precise about what end-to-end encryption (E2EE) does.
E2EE means that a message is encrypted on the sender’s device and can only be decrypted on the recipient’s device. No one in between — not the messaging provider, not the carrier, not a government intercepting traffic — can read the content without access to one of the two devices.
This is different from server-side encryption or “encryption in transit,” where the provider encrypts your data but holds the keys. With E2EE, the provider never has the keys.
For RCS messaging, E2EE applies to the transmission of messages and media. A photo you send over E2EE RCS is protected while it travels from your phone to your contact’s phone.
What RCS E2EE Does Not Protect
This is where it’s important to read past the headlines.
Your cloud backups
When you send a photo via iPhone, iMessage, or RCS, that photo typically also lives in your Photos app. If you have iCloud Photos enabled, it gets uploaded to Apple’s servers. Unless you have Advanced Data Protection (ADP) enabled on your Apple account, iCloud Photo Library is encrypted at rest using keys Apple holds — meaning Apple can access your photos if legally compelled.
Similarly, if you’re on Android and Google Photos backup is enabled, your photos upload to Google’s servers. Google has server-side encryption but can access your content.
Sending a photo over E2EE RCS doesn’t change any of that. The encrypted channel protects the message in transit. What either party does with the photo after receiving it — storing it in an unencrypted cloud backup, sharing it, or forwarding it — is outside the scope of the encryption.
Message history storage
Even if messages travel end-to-end encrypted, how they’re stored on each device matters. If a recipient backs up their phone to an unencrypted cloud backup, your encrypted messages become accessible through that backup.
Apple’s iMessage has historically struggled with this: iCloud backups that include iMessage history are encrypted using a key Apple holds (unless you enable ADP), which has made iMessage effectively accessible to Apple and law enforcement through backup requests, even though the messages themselves are E2EE.
RCS history stored in Google Messages can similarly end up in Google account backups.
Media sent to group chats
Group RCS chats with mixed iPhone and Android users may not yet be fully encrypted in all configurations, depending on carrier support and the RCS implementation. Apple and Google’s announcement focused primarily on one-to-one encrypted conversations. Large group chats may fall back to older, unencrypted channels if not all participants are on supported versions.
Carrier metadata
Even with E2EE, your carrier can see metadata: who you messaged, when, how often, and how large each message was. They don’t see the content, but metadata alone can be revealing. This is true of all encrypted messaging systems that route through carrier infrastructure.
The Gap Between “Encrypted Messaging” and “Private Storage”
One conceptual mistake people make when they hear about encrypted messaging is assuming it solves their personal file storage problem.
It doesn’t.
Messaging apps are designed to transmit information from person to person. They are not designed to be personal file vaults. A photo you send to yourself in a chat thread — whether in iMessage, WhatsApp, Signal, or now encrypted RCS — is in a completely different position than a photo you’ve stored in a dedicated, private cloud service.
The differences are:
Persistence: Messages can be deleted, threads can expire, apps can lose data. A dedicated personal file store is built for retention.
Access: Messaging apps are optimized for conversation flow, not for searching and retrieving specific files later. Finding a photo you sent to yourself in a text thread three years ago is a frustrating experience.
Backup risk: As described above, messaging histories often end up in phone backups that have less protection than the messages themselves.
Purpose-built security: Encrypted messaging is designed for communication security, not document management. A service built specifically for private personal storage can implement controls that messaging apps don’t offer.
What the RCS Update Actually Tells Us
The May 2026 RCS update is genuinely good news. For the first time, two people on different smartphone platforms can exchange a photo over an encrypted channel without needing to switch to a third-party app like Signal.
That’s a meaningful baseline improvement for the majority of phone-to-phone photo sharing. It closes a gap that existed for well over a decade.
But it’s worth understanding the scope of what changed. The update secures the channel between devices. It doesn’t change what happens to those photos once they arrive. It doesn’t change how photos are stored on each device, backed up, or synced to the cloud.
For people who want genuine end-to-end control over their personal photos and files — from creation to long-term storage — encrypted messaging is one piece of a larger picture, not the whole solution.
How to Confirm RCS Encryption Is Active
If you’re on iOS 26.5 or later:
- Open a conversation with an Android user in Apple’s Messages app
- Look for a lock icon near the conversation or the send button
- The presence of the lock indicates the conversation supports E2EE RCS
If you’re on Android with Google Messages:
- Open a conversation
- Tap the name at the top to see conversation details
- Look for “Encryption active” or a similar indicator
Keep in mind that both parties need to be on a supported OS version and using a compatible carrier. If the indicator isn’t present, the conversation may still be falling back to SMS.
What to Actually Do With This
If you’re already in the habit of assuming your text messages are private, the May 2026 update makes that assumption significantly more accurate for iPhone-to-Android conversations. That’s worth knowing and worth acting on — it’s now reasonable to share more sensitive content via text without the carrier being able to read it.
What the update doesn’t do is give you a private archive for your personal photos and files. For that, you need a service built for the job: something with its own access controls, its own encryption model, and its own long-term storage guarantees that aren’t dependent on your messaging history or your phone backup settings.
The distinction matters because people’s actual privacy risk isn’t usually “someone intercepting my texts in transit.” It’s more often “what does Google have access to? What does Apple have access to? Where do my files actually live?”
E2EE RCS answers the first question for the specific case of messages sent between phones. It leaves the second set of questions entirely untouched.